HonestClaw
What is Agent Readiness?

Agent Readiness Score

vanta.com

50 — Developing. Agents can find parts of this site, but key capabilities are hard to reach.

45 of 45 checks conclusive · Confidence High · Evidence coverage 100%

HonestClaw measured how well vanta.com's site and APIs work for AI agents — across 9 dimensions and 45 automated checks.

Dimensions

Discoverability12.6/24
Content Accessibility12.3/24
Bot Access Control0/12
Protocol & Capability Discovery22.4/41
Authentication & Credentials10/19
Documentation Quality8.5/10
Structured Data I/O8.1/13
Observable State & Reliability2.5/15
Agent Safety & Trust7.7/11

Checks

Discoverability

Subdomain sweepsubdomain-sweepAn agent-relevant subdomain is live and serves its expected content kind (developer.vanta.com).Parseable
Canonical domaincanonical-domainRoot and www converge on www.vanta.com, with a matching canonical tag.Cross-verified
robots.txtrobots-txtrobots.txt at https://vanta.com/robots.txt declares a sitemap. Declared sitemap https://www.vanta.com/sitemap.xml resolves as valid XML.Cross-verified
sitemap.xmlsitemap-xmlhttps://www.vanta.com/sitemap.xml is a dated sitemap whose URLs include docs/pricing/api surfaces.Cross-verified
API existenceapi-existenceA real API surface is declared at https://developer.vanta.com/api-reference/openapi.json: the spec lists servers and paths. (source: spec)Parseable
API catalogapi-catalogNo RFC 9727 API Catalog found at /.well-known/api-catalog.Not detected
API versioningapi-versioningThe API version is declared in the spec (info.version) at https://developer.vanta.com/api-reference/openapi.json. (source: spec)Parseable

Content Accessibility

Markdown twinmarkdown-twinA markdown twin is published at https://developer.vanta.com/index.md alongside the docs HTML surface (https://developer.vanta.com/).Parseable
Freshness signalsfreshness-signalsFreshness signals present: Last-Modified header, sitemap lastmod.Useful
Crawl-cost estimatecrawl-cost-estimateInformational — not scoredSitemap declares 3178 page URLs — moderate crawl cost; agents should budget accordingly.Parseable
Raw content extractabilityraw-content-extractabilitySubstantial visible text (12,484 chars) is readable without JavaScript on at least one probed page.Useful
llms.txtllms-txtA curated llms.txt index is published on a non-top subdomain at https://developer.vanta.com/llms.txt: 375 links across 2 sections. Its credit is capped at useful because it is not published on the main domain.Useful
llms-full.txtllms-full-txtNo llms-full.txt file found (HTML pages at .txt paths do not qualify).Not detected
ai.txtai-txtNo ai.txt file found (HTML pages at .txt paths do not qualify).Not detected

Bot Access Control

AI bot rulesai-bot-rulesrobots.txt is readable but declares no AI-bot-specific rules.Not detected
Content signalscontent-signalsrobots.txt is readable but declares no Content-Signal line.Not detected
RSL licensingrslrobots.txt is readable but declares no RSL License directive.Not detected
TDM reservationtdmrepNo TDMRep policy found at /.well-known/tdmrep.json.Not detected

Protocol & Capability Discovery

MCP descriptormcp-descriptorInformational — not scoredAn MCP server is described at https://developer.vanta.com/.well-known/mcp.json, but the description doesn't include a web address for the server.Parseable
MCP supportmcp-supportFirst-party documentation at https://developer.vanta.com/docs/quickstart/remediate-with-mcp identifies the MCP endpoint https://mcp.vanta.com/mcp and explains both its capabilities and how clients connect or authenticate.Cross-verified
MCP Server Cardmcp-server-cardA file exists at https://developer.vanta.com/.well-known/mcp/server-card.json, but it doesn't contain the fields that describe an MCP Server Card.Detected
A2A Agent Carda2a-agent-cardAn A2A Agent Card at https://developer.vanta.com/.well-known/agent-card.json declares 1 skill(s) and a connectable endpoint.Useful
.well-known indexwell-known-indexNo non-owned /.well-known/ descriptors found.Not detected
DNS-AIDdns-aidNo DNS-AID index found at _index._agents.vanta.com.Not detected
SDK availabilitysdk-availabilitySDK libraries page at https://developer.vanta.com/docs/sdks: 2 GitHub repos, 0 registry links, 0 install commands (2 pointers).Cross-verified
GraphQL surfacegraphql-surfaceNo GraphQL transport surface found at conventional paths (GET-only; no introspection issued).Not detected
Auth discoveryauth-discoveryAgent-native auth discovery: a valid RFC 9728 PRM (via challenge) or a PRM plus a valid AS/OIDC descriptor.Cross-verified
Link headerslink-headersNo RFC 8288 Link headers found on any probed response.Not detected
OpenAPI specificationopenapi-specValid OpenAPI 3.1.0 spec at https://developer.vanta.com/api-reference/openapi.json: 3 operations, 3 schemas, 100% response coverage, servers declared.Cross-verified
Rate limit documentationrate-limit-docsNo rate limit documentation found at the standard docs locations an agent would check.Not detected
WebMCPwebmcpInformational — not scoredWebMCP browser probing is not yet available in this scanner release.Couldn't verify

Authentication & Credentials

Credential managementcredential-managementNo credential management documentation found at the standard docs locations an agent would check.Not detected
Sandbox environmentsandbox-environmentNo sandbox or test environment documentation found at the standard docs locations an agent would check.Not detected
Programmatic auth flowprogrammatic-auth-flowA programmatic auth flow is fully documented at https://developer.vanta.com/docs/concepts/authentication, with a non-interactive grant, token endpoint, scopes, and token expiry/refresh.Cross-verified
Auth documentationauth-documentationAuthentication is fully documented at https://developer.vanta.com/docs/concepts/authentication, naming complete method(s) and how they are sent, corroborated across surfaces or covering multiple methods.Cross-verified

Documentation Quality

Changelog presencechangelog-presenceA changelog is published at https://www.vanta.com/whats-new with multiple recent dated entries, indicating it is actively maintained.Cross-verified
API reference depthapi-reference-depthThe API reference at https://developer.vanta.com/api-reference/api-endpoint-vulnerabilities/list-all-api-endpoint-vulnerabilities documents parameters with example requests and responses. To reach the top level, it would need request and response bodies, authentication, pagination, and error codes.Useful

Structured Data I/O

Structured data I/Ostructured-data-ioThe spec at https://developer.vanta.com/api-reference/openapi.json declares typed, consistent response schemas (100% of operations) with a pagination pattern and a structured error envelope. (source: spec)Cross-verified
Machine-readable pricingmachine-readable-pricingA response at https://vanta.com/pricing.json looks JSON-like but did not parse as JSON.Detected
Data export APIdata-export-apiNo data export or bulk API documentation found at the standard docs locations an agent would check.Not detected

Observable State & Reliability

Status & health endpointsstatus-and-healthStatus page found at https://status.vanta.com/?_gl=1*4pxd79*_ga*NDg5MzMwMDg3LjE2NzY0NTAwMjc.*_ga_SW5LK36MTJ*MTY4MDIwODQzMy43Mi4xLjE2ODAyMDg3NTUuNjAuMC4w (HTTP 200).Detected
Retry & idempotencyretry-and-idempotencyNo retry or idempotency documentation found at the standard docs locations an agent would check.Not detected
Error documentationerror-documentationError handling is mentioned at https://www.vanta.com/resources/how-we-standardized-error-handling, but not on a page dedicated to documenting it.Detected
Webhook documentationwebhook-documentationA webhook documentation page exists at https://developer.vanta.com/docs/webhooks, but it doesn't list specific event types with their payload shape.Parseable
Machine payments (x402/MPP)x402-or-mpp-supportInformational — not scoredNo machine-payment signal observed (no HTTP 402, no payment-required response header, and no /.well-known/x402.json manifest). Payment support cannot be ruled out from an unauthenticated probe.Couldn't verify

Agent Safety & Trust

security.txtsecurity-txtsecurity.txt at https://vanta.com/.well-known/security.txt includes Contact, a future Expires date, and Encryption or Policy.Cross-verified
Org identity signalsorg-identityHomepage exposes one org-identity signal (social).Detected
Metadata consistencymetadata-consistencyHomepage metadata (canonical, Open Graph, schema) is present and consistent.Cross-verified
Legal policy pageslegal-pagesBoth privacy and terms policies are discoverable with substantive content.Useful